CVE Feed

    Dashboard / CVE

    4.3
    Medium

    CVE-2024-31239

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Nudgify Nudgify Social Proof, Sales Popup & FOMO.This issue affects Nudgify Social Proof, Sales Popup & FOMO: from n/a through 1.3.3.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31250

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Saumya Majumder WP Server Health Stats.This issue affects WP Server Health Stats: from n/a through 1.7.3.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31251

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in PeepSo Community by PeepSo.This issue affects Community by PeepSo: from n/a through 6.3.1.1.

    Published: 12 Apr 2024
    5.4
    Medium

    CVE-2024-31262

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Jcodex WooCommerce Checkout Field Editor (Checkout Manager).This issue affects WooCommerce Checkout Field Editor (Checkout Manager): from n/a through 2.1.8.

    Published: 12 Apr 2024
    5.4
    Medium

    CVE-2024-31263

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in aerin Loan Repayment Calculator and Application Form.This issue affects Loan Repayment Calculator and Application Form: from n/a through 2.9.4.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31264

    Last Modified: 15 Apr 2026

    Unauthenticated Cross Site Request Forgery (CSRF) in Post Views Counter <= 1.4.4 versions.

    Published: 12 Apr 2024
    3.7
    Low

    CVE-2024-31265

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in SumoMe Sumo.This issue affects Sumo: from n/a through 1.34.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31268

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in AppPresser Team AppPresser.This issue affects AppPresser: from n/a through 4.3.0.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31269

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Easy Google Maps.This issue affects Easy Google Maps: from n/a through 1.11.11.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31271

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Supsystic Ultimate Maps by Supsystic.This issue affects Ultimate Maps by Supsystic: from n/a through 1.2.16.

    Published: 12 Apr 2024
    6.3
    Medium

    CVE-2024-31272

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Repute InfoSystems ARForms Form Builder.This issue affects ARForms Form Builder: from n/a through 1.6.1.

    Published: 12 Apr 2024
    5.4
    Medium

    CVE-2024-31279

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Catch Plugins Generate Child Theme.This issue affects Generate Child Theme: from n/a through 2.0.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31289

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Elementor Hello Elementor.This issue affects Hello Elementor: from n/a through 3.0.0.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31293

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Easy Digital Downloads.This issue affects Easy Digital Downloads: from n/a through 3.2.6.

    Published: 12 Apr 2024
    5.4
    Medium

    CVE-2024-31301

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Themeisle Multiple Page Generator Plugin – MPG.This issue affects Multiple Page Generator Plugin – MPG: from n/a through 3.4.0.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31303

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets.This issue affects Sign-up Sheets: from n/a through <= 2.2.11.1.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31305

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in rtCamp Transcoder.This issue affects Transcoder: from n/a through 1.3.5.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31354

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Tribulant Slideshow Gallery.This issue affects Slideshow Gallery: from n/a through 1.7.8.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31360

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Coded Commerce, LLC Benchmark Email Lite.This issue affects Benchmark Email Lite: from n/a through 4.1.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31362

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Metagauss ProfileGrid.This issue affects ProfileGrid : from n/a through 5.7.8.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31363

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in LifterLMS.This issue affects LifterLMS: from n/a through 7.5.0.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31364

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in ELEXtensions ELEX WooCommerce Dynamic Pricing and Discounts.This issue affects ELEX WooCommerce Dynamic Pricing and Discounts: from n/a through 2.1.2.

    Published: 12 Apr 2024
    4.8
    Medium

    CVE-2023-47714

    Last Modified: 7 Mar 2025

    IBM Sterling File Gateway 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 271531.

    Published: 12 Apr 2024
    6.4
    Medium

    CVE-2024-27261

    Last Modified: 21 Nov 2024

    IBM Storage Defender - Resiliency Service 2.0.0 through 2.0.2 could allow a privileged user to install a potentially dangerous tar file, which could give them access to subsequent systems where the package was installed. IBM X-Force ID: 283986.

    Published: 12 Apr 2024
    —
    Unknown

    CVE-2024-3702

    Last Modified: 11 Feb 2025

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 12 Apr 2024
    7.2
    High

    CVE-2024-3054

    Last Modified: 8 Apr 2026

    WPvivid Backup & Migration Plugin for WordPress is vulnerable to PHAR Deserialization in all versions up to, and including, 0.9.99 via deserialization of untrusted input at the wpvividstg_get_custom_exclude_path_free action. This is due to the plugin not providing sufficient path validation on the tree_node[node][id] parameter. This makes it possible for authenticated attackers, with admin-level access and above, to call files using a PHAR wrapper that will deserialize the data and call arbitrary PHP Objects. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.

    Published: 12 Apr 2024
    8.8
    High

    CVE-2024-3211

    Last Modified: 15 Apr 2026

    The Shopping Cart & eCommerce Store plugin for WordPress is vulnerable to SQL Injection via the 'productid' attribute of the ec_addtocart shortcode in all versions up to, and including, 5.6.3 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with contributor-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31371

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Xylus Themes WP Event Aggregator.This issue affects WP Event Aggregator: from n/a through 1.7.6.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2024-31372

    Last Modified: 28 Apr 2026

    Cross-Site Request Forgery (CSRF) vulnerability in Arnan de Gans No-Bot Registration.This issue affects No-Bot Registration: from n/a through 1.9.1.

    Published: 12 Apr 2024
    10
    Critical

    CVE-2024-3400

    Last Modified: 4 Nov 2025

    A command injection as a result of arbitrary file creation vulnerability in the GlobalProtect feature of Palo Alto Networks PAN-OS software for specific PAN-OS versions and distinct feature configurations may enable an unauthenticated attacker to execute arbitrary code with root privileges on the firewall. Cloud NGFW, Panorama appliances, and Prisma Access are not impacted by this vulnerability.

    Published: 12 Apr 2024
    4.8
    Medium

    CVE-2023-45186

    Last Modified: 7 Mar 2025

    IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 268691.

    Published: 12 Apr 2024
    6.4
    Medium

    CVE-2024-2801

    Last Modified: 15 Apr 2026

    The Shopkeeper Extender plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'image_slide' shortcode in all versions up to, and including, 3.6 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Apr 2024
    6.4
    Medium

    CVE-2024-2137

    Last Modified: 8 Apr 2026

    The All-in-One Addons for Elementor – WidgetKit plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple pricing widgets (e.g. Pricing Single, Pricing Icon, Pricing Tab) in all versions up to, and including, 2.5.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Apr 2024
    5.4
    Medium

    CVE-2023-50307

    Last Modified: 7 Mar 2025

    IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 273338.

    Published: 12 Apr 2024
    5.4
    Medium

    CVE-2024-22357

    Last Modified: 7 Mar 2025

    IBM Sterling B2B Integrator 6.0.0.0 through 6.0.3.9, 6.1.0.0 through 6.1.2.3, and 6.2.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 280894.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2023-6489

    Last Modified: 20 Nov 2025

    A denial of service vulnerability was identified in GitLab CE/EE, versions 16.7.7 prior to 16.8.6, 16.9 prior to 16.9.4 and 16.10 prior to 16.10.2 which allows an attacker to spike the GitLab instance resources usage resulting in service degradation via chat integration feature.

    Published: 12 Apr 2024
    4.3
    Medium

    CVE-2023-6678

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab EE affecting all versions before 16.8.6, all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. It was possible for an attacker to cause a denial of service using malicious crafted content in a junit test report file.

    Published: 12 Apr 2024
    8.7
    High

    CVE-2024-2279

    Last Modified: 16 Dec 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.7 to 16.8.6 all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. Using the autocomplete for issues references feature a crafted payload may lead to a stored XSS, allowing attackers to perform arbitrary actions on behalf of victims.

    Published: 12 Apr 2024
    8.7
    High

    CVE-2024-3092

    Last Modified: 20 Nov 2025

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 16.9 before 16.9.4, all versions starting from 16.10 before 16.10.2. A payload may lead to a Stored XSS while using the diff viewer, allowing attackers to perform arbitrary actions on behalf of victims.

    Published: 12 Apr 2024
    6.1
    Medium

    CVE-2024-30845

    Last Modified: 17 Jun 2025

    Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation component of the input parameters.

    Published: 12 Apr 2024
    9.8
    Critical

    CVE-2024-31818

    Last Modified: 17 Jun 2025

    Directory Traversal vulnerability in DerbyNet v.9.0 allows a remote attacker to execute arbitrary code via the page parameter of the kiosk.php component.

    Published: 12 Apr 2024
    9.8
    Critical

    CVE-2024-28718

    Last Modified: 17 Jun 2025

    An issue in OpenStack magnum yoga-eom version allows a remote attacker to execute arbitrary code via the cert_manager.py. component.

    Published: 12 Apr 2024
    5.5
    Medium

    CVE-2024-22526

    Last Modified: 17 Jun 2025

    Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file.

    Published: 12 Apr 2024
    7.4
    High

    CVE-2024-27309

    Last Modified: 30 Jul 2025

    While an Apache Kafka cluster is being migrated from ZooKeeper mode to KRaft mode, in some cases ACLs will not be correctly enforced. Two preconditions are needed to trigger the bug: 1. The administrator decides to remove an ACL 2. The resource associated with the removed ACL continues to have two or more other ACLs associated with it after the removal. When those two preconditions are met, Kafka will treat the resource as if it had only one ACL associated with it after the removal, rather than the two or more that would be correct. The incorrect condition is cleared by removing all brokers in ZK mode, or by adding a new ACL to the affected resource. Once the migration is completed, there is no metadata loss (the ACLs all remain). The full impact depends on the ACLs in use. If only ALLOW ACLs were configured during the migration, the impact would be limited to availability impact. if DENY ACLs were configured, the impact could include confidentiality and integrity impact depending on the ACLs configured, as the DENY ACLs might be ignored due to this vulnerability during the migration period.

    Published: 12 Apr 2024
    6.5
    Medium

    CVE-2024-31391

    Last Modified: 17 Jun 2025

    Insertion of Sensitive Information into Log File vulnerability in the Apache Solr Operator. This issue affects all versions of the Apache Solr Operator from 0.3.0 through 0.8.0. When asked to bootstrap Solr security, the operator will enable basic authentication and create several accounts for accessing Solr: including the "solr" and "admin" accounts for use by end-users, and a "k8s-oper" account which the operator uses for its own requests to Solr. One common source of these operator requests is healthchecks: liveness, readiness, and startup probes are all used to determine Solr's health and ability to receive traffic. By default, the operator configures the Solr APIs used for these probes to be exempt from authentication, but users may specifically request that authentication be required on probe endpoints as well. Whenever one of these probes would fail, if authentication was in use, the Solr Operator would create a Kubernetes "event" containing the username and password of the "k8s-oper" account. Within the affected version range, this vulnerability affects any solrcloud resource which (1) bootstrapped security through use of the `.solrOptions.security.authenticationType=basic` option, and (2) required authentication be used on probes by setting `.solrOptions.security.probesRequireAuth=true`. Users are recommended to upgrade to Solr Operator version 0.8.1, which fixes this issue by ensuring that probes no longer print the credentials used for Solr requests.  Users may also mitigate the vulnerability by disabling authentication on their healthcheck probes using the setting `.solrOptions.security.probesRequireAuth=false`.

    Published: 12 Apr 2024
    8.2
    High

    CVE-2023-44852

    Last Modified: 27 May 2025

    Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the c_set_traps_decode function in the acu_web file.

    Published: 12 Apr 2024
    4.8
    Medium

    CVE-2023-44853

    Last Modified: 27 May 2025

    \An issue was discovered in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_219C4 function in the acu_web file.

    Published: 12 Apr 2024
    6.1
    Medium

    CVE-2023-44854

    Last Modified: 27 May 2025

    Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the c_set_rslog_decode function in the acu_web file.

    Published: 12 Apr 2024
    6.5
    Medium

    CVE-2023-44855

    Last Modified: 28 May 2025

    Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019 allows a remote attacker to execute arbitrary code via a crafted script to the rdiag, sender, and recipients parameters of the sub_219C4 function in the acu_web file.

    Published: 12 Apr 2024
    6.1
    Medium

    CVE-2023-44856

    Last Modified: 27 May 2025

    Cross Site Scripting (XSS) vulnerability in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the rstat, sender, and recipients' parameters of the sub_21D24 function in the acu_web file.

    Published: 12 Apr 2024